VYPR

WN535G3

by Wavlink

CVEs (6)

  • CVE-2022-35520CriAug 10, 2022
    risk 0.64cvss 9.8epss 0.02

    WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 api.cgi has no filtering on parameter ufconf, and this is a hidden parameter which doesn't appear in POST body, but exist in cgi binary. This leads to command injection in page /ledonoff.shtml.

  • CVE-2022-34577CriJul 25, 2022
    risk 0.64cvss 9.8epss 0.02

    A vulnerability in adm.cgi of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to execute arbitrary code via a crafted POST request.

  • CVE-2022-34576HigJul 25, 2022
    risk 0.49cvss 7.5epss 0.04

    A vulnerability in /cgi-bin/ExportAllSettings.sh of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to execute arbitrary code via a crafted POST request.

  • CVE-2022-31846HigJun 14, 2022
    risk 0.49cvss 7.5epss 0.07

    A vulnerability in live_mfg.shtml of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to obtain sensitive router information via execution of the exec cmd function.

  • CVE-2022-31845HigJun 14, 2022
    risk 0.49cvss 7.5epss 0.08

    A vulnerability in live_check.shtml of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to obtain sensitive router information via execution of the exec cmd function.

  • CVE-2022-30489MedMay 13, 2022
    risk 0.40cvss 6.1epss 0.04

    WAVLINK WN535 G3 was discovered to contain a cross-site scripting (XSS) vulnerability via the hostname parameter at /cgi-bin/login.cgi.